Untrusted Search Path Vulnerability in Simeji for Windows by Simeji
CVE-2017-2219

7.8HIGH

Key Information:

Vendor

Baidu

Status
Vendor
CVE Published:
9 June 2017

What is CVE-2017-2219?

The installer for Simeji for Windows has an untrusted search path vulnerability that enables attackers to exploit this flaw by placing a malicious DLL in an unspecified directory. This can lead to privilege escalation, allowing unauthorized users to gain higher access levels than intended. Affected systems may be at risk if this vulnerability is not addressed, making it crucial for users to ensure their installations are secure and up-to-date.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.